Senior DevSecOps Engineer

Greenboard

New York (NY)

Hybrid

USD 165,000 - 240,000

Full time

8 days ago

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Salary + equity
401(k) match
Medical/Dental/Vision
PTO & holidays
Remote days
Company off-sites

Job summary

Greenboard seeks a hands-on security engineer to own and scale our security posture as we grow. You'll be the first dedicated security hire on our engineering team, shaping how we think about security—from compliance frameworks and vendor diligence to infrastructure hardening and secure development practices.

This high-impact role will work closely with engineering, product, and business teams to ensure secure builds, meet the compliance bar fintech customers expect, and stay ahead of threats as

Qualifications

  • 5–10 years of experience in security engineering, application security, or infrastructure security roles.
  • Hands-on experience with SOC 2 audits and at least one other framework (GDPR, ISO 27001, PCI-DSS, etc.).
  • Strong technical foundation—able to read code, review AWS infrastructure, and work in CI/CD.
  • Experience with vulnerability tooling (Snyk, Semgrep, Qualys, Burp Suite).
  • Familiarity with AWS Secrets Manager and IAM best practices.
  • Experience coordinating third-party pentests.
  • Clear, low-ego communication; explain risks to engineers and compliance to sales.
  • Comfort with ambiguity and ownership; build-it role, not maintain-it.

Responsibilities

  • Detect, triage, and remediate vulnerabilities across the stack—infrastructure, app, and network.
  • Manage third-party penetration tests and coordinate internal response.
  • Integrate security into the development lifecycle: guardrails, SAST/DAST tooling, dependency scanning, guidance.
  • Own credential and secrets management, including rotation, vault config, and access controls.
  • Manage infrastructure patching and hardening with engineering to avoid delivery disruption.

Skills

Security engineering
Application security
Infrastructure security
Vulnerability management
AWS
CI/CD
Threat modeling
Communication
Ownership

Tools

Snyk
Semgrep
Qualys
Burp Suite
AWS Secrets Manager
IAM best practices

Job description

About Greenboard

At Greenboard, we’re building the future of financial compliance. Greenboard is the unified, AI-native compliance operating system for RIAs, fintechs, private funds, hedge funds, and more. It replaces the fragmented mix of legacy tools and automates more than previously possible. By centralizing data and workflows, Greenboard helps firms reduce regulatory risk, simplify their technology stack, modernize how they run compliance, and save money.

Our founding team includes engineers who have scaled products at Amazon, Google, and multiple unicorn startups. We’re backed by Y Combinator, General Catalyst, Base10, and other top-tier investors, and have raised over $20M to date. Brand-name financial institutions already rely on Greenboard — and we’re growing fast.

About the Role

We're looking for a hands-on security engineer to own and scale our security posture as we grow. You'll be the first dedicated security hire on our engineering team, which means you'll have a direct hand in shaping how we think about security — from compliance frameworks and vendor diligence to infrastructure hardening and secure development practices.

This is a high-impact, high-autonomy role. You'll work closely with engineering, product, and business teams to make sure we're building securely, meeting the compliance bar our fintech customers expect, and staying ahead of threats as we expand internationally.

What You'll Do
Technical Security
  • Detect, triage, and drive remediation of vulnerabilities across the stack — infrastructure, application, and network.

  • Manage third-party penetration tests and coordinate internal response to findings.

  • Integrate security into the development lifecycle: code review guardrails, SAST/DAST tooling, dependency scanning, and developer security guidance.

  • Own credential and secrets management, including rotation policies, vault configuration, and access controls.

  • Manage infrastructure patching and hardening, working with engineering to keep systems current without disrupting delivery.

Security Compliance & Frameworks
  • Own our SOC 2 compliance program end-to-end, including audit preparation, evidence collection, and remediation tracking.

  • Maintain and mature our GDPR compliance posture, partnering with legal and product to ensure data protection requirements are met.

  • Lead our ISO 42001 certification efforts, establishing and maintaining the required AI management system controls.

  • Research and implement additional compliance frameworks as we expand into new markets, acting as the internal authority on what's required and when.

Vendor & Customer Security Diligence
  • Manage inbound security diligence requests that arise during client sales processes — completing questionnaires, coordinating evidence, and joining calls as needed.

  • Build and maintain a vendor security review process for evaluating third-party tools and services before they're adopted.

  • Maintain a library of up-to-date security documentation (policies, SOC 2 reports, architecture diagrams) to accelerate deal cycles.

IT & Device Security
  • Manage endpoint security across the company — MDM, disk encryption, OS patching, and device compliance policies.

  • Maintain and enforce access control policies for corporate tools and systems (SSO, MFA, least-privilege access).

What We're Looking For
  • 5–10 years of experience in security engineering, application security, or infrastructure security roles.

  • Hands-on experience with SOC 2 audits and at least one other compliance framework (GDPR, ISO 27001, PCI-DSS, or similar).

  • Strong technical foundation — you're comfortable reading code, reviewing AWS infrastructure, and working in a CI/CD environment.

  • Experience with vulnerability management tooling (e.g., Snyk, Semgrep, Qualys, Burp Suite, or equivalents).

  • Familiarity with AWS Secrets Manager and IAM best practices.

  • Experience managing or coordinating third-party pentests.

  • Clear, low-ego communication style — you can explain a risk to an engineer and a compliance requirement to a salesperson with equal clarity.

  • Comfort with ambiguity and ownership. This is a build-it role, not a maintain-it role.

Nice to Have
  • Prior experience at a fintech or other regulated-industry startup.

  • Familiarity with ISO 42001 or AI governance frameworks.

  • Experience with MDM platforms

  • Background supporting international expansion from a security/compliance perspective.

Benefits
  • Salary range: $165,000–$240,000 + meaningful equity

  • 401(k) with 5% company match

  • Medical, dental, and vision coverage

  • 15 days PTO + 11 company holidays + flexible sick time

  • 2 additional PTO days for each year of service (up to 10 additional days)

  • 10 remote days per year plus additional around the holidays

  • Bi-annual off-sites and team retreats

  • Front-row seat to building the operating backbone of modern finance

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Customer Success Manager
Customer Success Manager

Greenboard • New York (NY)

On-site
USD 110,000 - 150,000
Equity
401(k) match
Medical/Dental/Vision
+4
Senior Security Automation Engineer
Senior Security Automation Engineer

Beyond Finance • Chicago (IL)

On-site
USD 160,000 - 195,000
Health, dental, and vision coverage
Generous PTO and paid holidays
401(k) matching
Business Development Representative
Business Development Representative

Greenboard • Phoenix (AZ)

On-site
USD 85,500 - 104,500
401(k) with 5% company match
$95,000 OTE
Medical, dental, and vision coverage
+2
VP, Infrastructure and Security
VP, Infrastructure and Security

floatme • San Antonio (FL)

On-site
USD 210,000 - 320,000
Senior Staff Product Security Engineer
Senior Staff Product Security Engineer

Capitolis • Atlanta (GA)

Hybrid
USD 180,000 - 240,000
Medical, dental, and vision plans
401k with company match
Unlimited PTO
+1
Senior Corporate Security Engineer
Senior Corporate Security Engineer

United States Digital Space LLC • Bellevue (CA)

Hybrid
USD 166,000 - 195,000
Health insurance
Equity ownership
401(k) matching
+2
Security Lead
Security Lead

Taktile • United States

On-site
USD 180,000 - 260,000
Equity package
Competitive compensation
Self-development budget
+1
Compliance Operations Lead
Compliance Operations Lead

GovSignals • New York (NY)

On-site
USD 140,000 - 190,000
100% employer-paid medical, vision, and dental
Unlimited PTO
Equity in a fast-growing startup
Senior DevSecOps Engineer - Build Secure FinTech Platform
Senior DevSecOps Engineer - Build Secure FinTech Platform

Greenboard • New York (NY)

Hybrid
USD 165,000 - 240,000
Salary + equity
401(k) match
Medical/Dental/Vision
+3
Sr. Product Security Engineer
Sr. Product Security Engineer

United States Digital Space LLC • New York (NY)

Hybrid
USD 175,000 - 205,000